Out-of-bounds read in msgpack5 - #VU152783
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the msgpack5 decoder when processing a truncated map32 header. A remote attacker can send truncated map32 data to cause a denial of service.
No adjacent memory is disclosed because buffer bounds are checked.